Splunk Search

External IP location

Meena27
Explorer

Hi,

We have set to receive alerts like Brute force, Port Scanning from external IPs.

Is there anyway or query in Splunk to get the Country information about the External IP?

Tags (1)

MuS
SplunkTrust
SplunkTrust

Hi Meena27,

sure there is, you can use iplocation to get this kind of information and use geostats to show it on a google map inside Splunk.

cheers, MuS

Meena27
Explorer

Thanks MuS.

Please let me know how to install the Geo IP app and is Google Map is necessary for that?

0 Karma

jmeyers_splunk
Splunk Employee
Splunk Employee

you don't need an app for this. these commands are built into splunk. just have a search that includes an ip address, pipe that to iplocation and then pipe that to geostats. for example:

sourcetype=access_combined | iplocation clientip | geostats count

With that and 6.1+ you will have the option for "map" visualization. You can also supply anything to iplocation which is an IP and other aggregate operations to geostats. See the references for the search commands that @MuS already included above.

0 Karma
Get Updates on the Splunk Community!

Devesh Logendran, Splunk, and the Singapore Cyber Conquest

At this year’s Splunk University, I had the privilege of chatting with Devesh Logendran, one of the winners in ...

There's No Place Like Chrome and the Splunk Platform

WATCH NOW!Malware. Risky Extensions. Data Exfiltration. End-users are increasingly reliant on browsers to ...

Customer Experience | Join the Customer Advisory Board!

Are you ready to take your Splunk journey to the next level? 🚀 We invite you to join our elite squad ...